🔐 CVE Alert

CVE-2026-25600

MEDIUM 6.4

Credential Exposure Vulnerability in Trac PDBM

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
1th

The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the function responsible for decrypting credentials stored in the product’s configuration file. Because the secret is constant across installations, any attacker with sufficient local privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored password and authenticate as the user defined in the configuration file. In the affected version, this user account is configured with administrative privileges, granting full access to PDBM’s management interface and its underlying operational functions.

CWE CWE-798
Vendor trac d.o.o.
Product pdbm
Published Jun 1, 2026
Last Updated Jun 1, 2026
Stay Ahead of the Next One

Get instant alerts for trac d.o.o. pdbm

Be the first to know when new medium vulnerabilities affecting trac d.o.o. pdbm are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Trac d.o.o. / PDBM
0 < 2.0.0.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.si: https://www.cert.si/en/cve-2026-25600/

Credits

Mijo Mišić, Combis d.o.o.